The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
https://wpscan.com/vulnerability/7283a28a-7241-4b9e-8fc5-5b427191c80e/